For many security teams, the expected route into the corporate network begins with a phishing email or exploited vulnerability. Certain techniques differ, exploiting the hiring process to gain legitimate access.
In July, the US Department of State released an alert warning of North Korean IT workers impersonating nationals of other countries for the purpose of obtaining work. Once employed, those workers then send their salaries back to parent agencies in North Korea.
The FBI has also warned that fraudulent workers may use their access to copy source-code repositories, exfiltrate proprietary information and support other cybercriminal activity. After being discovered or dismissed, some have attempted to extort their employers by threatening to publish stolen code and data.
These operations expose a gap between checking an identity and proving who is using an account. For instance, a résumé may appear credible, and a laptop may arrive at a domestic address. But, neither of those controls, on its own, proves that the person interviewed is the person who receives the device, or the person who ultimately signs in.
The challenge for service desk agents is how they can confirm the person requesting access is both real and a legitimate new hire.
How Fake Remote Workers Defeat Recruiting Controls
Changing their nationality or identity: This is a key tactic of North Korean IT workers, who will falsify information when registering for online platforms. This might include forging identification documents, impersonating another person, or using a proxy to register an account.
Create fake profiles using AI: To add legitimacy to their identities, fake workers may also create professional profiles and social media accounts. They use AI to support these efforts, matching tone and language to real IT professionals.
Unorthodox payment methods: Fake workers may attempt to avoid being paid by direct deposit, instead favoring money transfers or cryptocurrency. North Korean workers have been observed using a third party for salary deposits, paying the third party for use of the account.
Disguising their location: Tools such as VPNs and remote desktop software may be used to hide the fact that a person is working from abroad.
... continue reading